Malware & C2

Malware & C2

Living-off-the-Land Binaries (LOLBins) for Evasion

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Malware & C2

C2 Frameworks Compared: Cobalt Strike, Sliver, and Mythic

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Malware & C2

AMSI Bypass Techniques and Defensive Hardening

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Malware & C2

Beacon Object Files and In-Memory Tradecraft

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Malware & C2

Persistence Techniques on Windows: Run Keys to WMI

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Malware & C2

Malleable C2 Profiles and Network Signature Evasion

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Malware & C2

Shellcode Loaders and Common Evasion Patterns

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Malware & C2

Anti-Debugging and Unpacking Malware Samples

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Linux Privesc

Linux Persistence: systemd Timers, udev Rules, and PAM Modules

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Malware & C2

COM Hijacking for Persistence and Privilege Escalation

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Malware & C2

Abusing BITS Jobs for Download and Persistence

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Malware & C2

Building a Malware Analysis Lab with REMnux and FLARE-VM

A practical guide to building an isolated REMnux + FLARE-VM lab with snapshots, INetSim, and FakeNet for safe malware analysis.
Malware & C2

Static Analysis of Windows PE Files: Headers, Imports, Strings, and capa

A practical walkthrough of statically triaging Windows PE files using pestudio, capa, and the CLI — plus blue-team detection.
Malware & C2

Dynamic Malware Analysis in a Sandbox: A Practical Behavioral Workflow

A hands-on guide to dynamic malware analysis with Procmon, Process Hacker, and Wireshark, plus Blue Team detection.
Malware & C2

Unpacking Packed Malware: From UPX to Custom Packers

A hands-on guide to manually unpacking UPX and custom packers using entropy, OEP detection, x64dbg, and Scylla import rebuild.
Malware & C2

Windows Shellcode: Writing and Analyzing Position-Independent Payloads

Build a position-independent Windows shellcode with PEB walking and API hashing, then dissect it with scdbg and a debugger.
Malware & C2

Process Injection Internals: DLL Injection, Reflective Loading, and Process Hollowing

A practical breakdown of classic DLL injection, reflective loading, and process hollowing on Windows, plus blue-team detection.
Malware & C2

Writing Effective YARA Detection Rules

A practical guide to writing precise YARA rules using strings, hex patterns, imphash, and conditions for malware detection.
Malware & C2

C2 Frameworks Explained: Cobalt Strike, Sliver, and Mythic

A practical tour of Cobalt Strike, Sliver, and Mythic — beacons, listeners, malleable profiles, redirectors, and OPSEC for red and blue teams.
Malware & C2

Dissecting Malicious Office Documents: VBA Macros, Stomping, and IOC Extraction

A hands-on guide to triaging malicious Office maldocs with oletools, defeating VBA stomping, and extracting IOCs.